Cyber Defense Using State Forensics Graphs for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cyber-attack detection methods, such as rule-based and signature-based systems, are inadequate in detecting advanced persistent threats (APT) and predicting next phases of attacks, as they often require time to generate signatures and may not consider system-wide or cross-system analytics, leading to vulnerabilities in defense posture against unseen attacks.

Innovation Solution

The use of state forensics graphs (SFGs) to model and correlate device states across space and time, enabling the detection of cyber-attacks by analyzing changes in system states, with correlation processes identifying benign or malicious changes, and providing real-time alerts or quarantining compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based detection processes are used to detect cyber-attacks, then detection accuracy for known threats is improved, but response time is increased due to the time required to generate signatures

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by generating attack genomes in advance from captured attack patterns. These pre-generated attack genomes are stored and ready for immediate comparison with current system states, eliminating the time required to generate detection signatures when an attack is suspected. The attack genome generation process captures the essence of attack patterns beforehand, enabling rapid detection without real-time signature generation delays.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If signature-based detection is used for individual files or processes, then detection specificity is improved, but system-wide threat detection capability is reduced

Engineering Contradiction:
Improvedetection specificityVSAvoidsystem-wide detection capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system merges individual file and process detection capabilities with system-wide analysis by integrating data from multiple sources including memory states, process information, and system-level metrics. The attack genome framework combines these diverse data types into a unified detection model that maintains specificity for individual components while simultaneously providing system-wide threat detection capability through correlated analysis.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of manufacture

If conventional detection methods are used, then implementation simplicity is maintained, but ability to detect advanced persistent threats is reduced

Engineering Contradiction:
Improveimplementation simplicityVSAvoidAPT detection capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system transitions from traditional single-dimension signature matching to multi-dimensional analysis by incorporating temporal, spatial, and behavioral dimensions. Attack genomes capture attack patterns across multiple dimensions including time sequences, system state transitions, and behavioral correlations. This dimensional expansion enables detection of sophisticated APTs that evade conventional single-dimension detection methods while building upon existing detection infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10706144B1Cyber defense with graph theoretical approach
Publication Date: 2020.07.07 BLUERISC INC
  • US10706144B1 patent drawing
  • US10706144B1 patent drawing
  • US10706144B1 patent drawing

AI summary

An example process that is performed by one or more processing devices uses one or more system states to detect cyber-attacks. The example process includes the following operations: generating a first graph that models states based on information obtained from an electronic device; and performing a correlation of the first graph with one or more second graphs to detect a possibility of a cyber-attack against the electronic device.